external-secrets:
  installCRDs: true
  webhook:
    create: true
  certController:
    create: true
  # serviceAccount IRSA ARN is injected per-environment
  # via helm.valuesObject in applications.yaml
  serviceAccount: {}
